Django 3.2.10 release notesLink to this heading
December 7, 2021
Django 3.2.10 fixes a security issue with severity "low" and a bug in 3.2.9.
CVE-2021-44420: Potential bypass of an upstream access control based on URL pathsLink to this heading
HTTP requests for URLs with trailing newlines could bypass an upstream access control based on URL paths.
BugfixesLink to this heading
Fixed a regression in Django 3.2 that caused a crash of
setUpTestData()withBinaryFieldon PostgreSQL, which ismemoryview-backed (#33333).